Data Breaches

CareCloud Data Breach Impacts Over 350,000

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data breach

Healthcare information technology company CareCloud is notifying at least 350,000 people that their information was stolen in a data breach.

The incident involved an electronic health record environment within the CareCloud Health division, which was disrupted on March 16, 2026.

CareCloud’s investigation determined that hackers accessed one of its AWS environments between March 10 and March 16, and likely exfiltrated data from it.

On June 24, the investigation determined that personal, financial, and medical information was compromised in the incident, the company notes in the notification letter sent to the potentially affected individuals, a copy of which was filed with the Massachusetts Office of Consumer Affairs and Business Regulation.

The potentially affected information, it says, includes names, addresses, Social Security numbers, dates of birth, driver’s license numbers, government ID numbers, financial account numbers, credit/debit card numbers, and medical and health insurance information.

Based on filings with the Attorney General’s Offices in several states, at least 350,000 individuals have had their information stolen.

Advertisement. Scroll to continue reading.

The company is providing them with up to 24 months of free identity theft protection, credit monitoring, and ID theft recovery services, which include a $1,000,000 insurance reimbursement policy.  

“CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments,” the company says.

The healthcare organization has yet to share the total number of impacted individuals and details on the threat actor responsible for the attack. SecurityWeek has emailed CareCloud for additional details and will update this article if the company responds.

Related: Semiconductor Firm Analog Devices Discloses Data Breach

Related: ShinyHunters Claims Ernst & Young Hack

Related: Origin Energy Data Breach Affects 900,000 Australians

Related: Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Related Content

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Data Breaches

The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Data Breaches

Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version